Email Security

Your Business Email Server Can Be Attacked Before Anyone Opens the Message

A new Exchange Server flaw shows why small-business email infrastructure can be attacked before anyone clicks – and what to verify now.

In this article:

  • Why an email server can be attacked before an employee clicks
  • What public exposure can – and cannot – prove
  • Five questions to ask your IT provider now

The attack may start before anyone clicks

Most email-security advice focuses on suspicious links and attachments. That advice still matters, but it is not the whole story.

On September 8, 2026, Microsoft released updates for CVE-2026-55007, a remote-code-execution vulnerability in Microsoft Exchange Server. The Zero Day Initiative reported that an unauthenticated attacker could try to exploit an affected server by sending an email with a malicious Visio attachment. The server processes the message, so the recipient may not need to open or preview it.

The practical question for a business owner is not only “Will someone click?” It is also “What system is receiving and processing our email?”

Why small and midsize businesses should care

Business email often carries the information and decisions that keep a company moving:

  • Customer and supplier conversations
  • Invoices, payment instructions and contracts
  • Password-reset messages
  • Schedules and operational decisions
  • Employee and customer information

Microsoft 365 does not always mean cloud-only email

Many companies use Microsoft 365 and assume Microsoft operates every part of their email environment. That may be true, but some businesses still have an on-premises Exchange Server for hybrid features, mail routing, administration or a legacy setup.

Leadership may never see that server. If it accepts email from the internet, however, it is still part of the company’s external attack surface.

Publicly visible does not mean vulnerable or compromised

These findings are different and should not be treated as interchangeable:

Visible means public records or an outside observation suggest that email infrastructure exists or a related service is reachable. Vulnerable means internal verification confirms that an affected Exchange version is installed and the required update is missing. Compromised means logs, forensic evidence or other findings show unauthorized activity.

An outside review generally cannot prove the exact software version, patch status or whether the system was breached. Microsoft said CVE-2026-55007 was not publicly disclosed or known to be actively exploited when the update was released, and that successful exploitation would be difficult. That is a reason to verify – not a reason to panic.

Five questions to ask your IT provider

Ask for clear answers and the evidence behind them:

  • Do we operate any on-premises Microsoft Exchange Server?
  • Is an Exchange server still present because of a hybrid Microsoft 365 setup?
  • Which version and build is installed?
  • Was the September 8, 2026 Exchange security update applied?
  • What evidence confirms these answers?

If you use Exchange Online only

If your business uses Exchange Online exclusively and has no on-premises Exchange Server, this particular server vulnerability may not apply. Your MSP or Microsoft 365 administrator should be able to confirm that clearly.

How an independent review can help

The free Zero-Access Business Exposure Review™ examines public information associated with your company’s email, domains, websites and internet-facing services. It requires no passwords or internal access and gives you a plain-English conclusion, questions to take to your IT provider and a recommended first step.

A public review cannot confirm an internal Exchange version or patch. The $1,995 Business Security Baseline goes further by reviewing evidence for essential safeguards, including email protection, Microsoft 365 identity, administrative controls, devices, patching, backups and logging. It is available for businesses with up to 25 employees; larger environments receive a confirmed quote after scoping.

The goal is not to replace your MSP. It is to help leadership separate what is publicly observable from what has been verified internally.

Know what is receiving your company’s email

The lesson from CVE-2026-55007 is broader than one Microsoft vulnerability: a system does not need to show an obvious login screen to be an internet-facing asset. Sometimes the exposed door is simply the server accepting the next message.

Start with a free Zero-Access Business Exposure Review™ to understand what the public internet can observe and what your business should verify next.

Related resources

Sources

Need an evidence-backed starting point?

The free Exposure Review shows what is publicly observable. The Business Security Baseline verifies the essential controls protecting the business.